Getting Data In

How to monitor Windows SMTP relay data to find rejections?

brent_weaver
Builder

My team and I are integrating our monitoring tools into our ticketing system. To open a ticket I need to email a specific address, and if the format of the email is one char off, or there is a config item that does not exist, it will drop and and nothing will get done. So I turn to splunk 🙂

How can I log on my Windows smtp relay server to detect such events, and for that matter all events!

Thanks!

0 Karma

bryan_dady
Explorer

Have you enabled SMTP Logging in your IIS configs?
If so, you can point your forwarders to index those logs, and then search them.

0 Karma

s2_splunk
Splunk Employee
Splunk Employee

Have you taken a closer look at the Splunk App for Exchange? I am not familiar with how the Windows SMTP relay server logs, so it's hard to answer your specific question.
An alternative approach may be to use the Splunk App for Stream, which supports smtp protocol analysis in Splunk directly off the wire.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...